CVE-2025-45424: Medium severity Xinference Xinference vulnerability
Published Jul 2, 2025
·Updated
Incorrect access control in Xinference before v1.4.0 allows attackers to access the Web GUI without authentication.
Affected Software
2 affected components
Xinference Xinference<1.4.0
Xinference Xinference<1.4.0
Event History
Jul 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-45424?
CVE-2025-45424 is considered a high-severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2025-45424?
To fix CVE-2025-45424, upgrade Xinference to version 1.4.0 or later.
3
What does CVE-2025-45424 affect?
CVE-2025-45424 affects Xinference software versions prior to 1.4.0.
4
What is the nature of the vulnerability in CVE-2025-45424?
CVE-2025-45424 involves incorrect access control, allowing attackers to access the Web GUI without authentication.
5
Is CVE-2025-45424 related to user authentication?
Yes, CVE-2025-45424 is specifically related to the lack of required user authentication for accessing the Web GUI.